Re: [Openstack] Admin-ness in Keystone, Nova, et. al.

2012-03-30 Thread Julien Danjou
On Fri, Mar 30 2012, Gabriel Hurley wrote: In practice today, Keystone no longer has global roles, and RBAC implementation isn't fully there yet across the ecosystem. So projects have adopted inconsistent means of determining when and how to grant admin-level privileges to that user. This

Re: [Openstack] Admin-ness in Keystone, Nova, et. al.

2012-03-30 Thread Vishvananda Ishaya
On Mar 30, 2012, at 7:41 AM, Julien Danjou wrote: On Fri, Mar 30 2012, Gabriel Hurley wrote: In practice today, Keystone no longer has global roles, and RBAC implementation isn't fully there yet across the ecosystem. So projects have adopted inconsistent means of determining when and how to

Re: [Openstack] Admin-ness in Keystone, Nova, et. al.

2012-03-30 Thread Yee, Guang
Danjou Cc: openstack@lists.launchpad.net Subject: Re: [Openstack] Admin-ness in Keystone, Nova, et. al. Commented on the first bug. On Fri, Mar 30, 2012 at 7:41 AM, Julien Danjou julien.dan...@enovance.com wrote: On Fri, Mar 30 2012, Gabriel Hurley wrote: In practice today, Keystone

Re: [Openstack] Admin-ness in Keystone, Nova, et. al.

2012-03-30 Thread Jay Pipes
FWIW, it is possible in Glance to set the configuration option admin_role value to something other than admin -- for instance glance:admin -- to use a different role than admin to indicate a role that should only be able to admin Glance and not other endpoints.

Re: [Openstack] Admin-ness in Keystone, Nova, et. al.

2012-03-30 Thread Yee, Guang
@lists.launchpad.net] On Behalf Of Jay Pipes Sent: Friday, March 30, 2012 11:33 AM To: openstack@lists.launchpad.net Subject: Re: [Openstack] Admin-ness in Keystone, Nova, et. al. FWIW, it is possible in Glance to set the configuration option admin_role value to something other than admin

Re: [Openstack] Admin-ness in Keystone, Nova, et. al.

2012-03-30 Thread Jay Pipes
To: openstack@lists.launchpad.net Subject: Re: [Openstack] Admin-ness in Keystone, Nova, et. al. FWIW, it is possible in Glance to set the configuration option admin_role value to something other than admin -- for instance glance:admin -- to use a different role than admin to indicate a role that should only

[Openstack] Admin-ness in Keystone, Nova, et. al.

2012-03-29 Thread Gabriel Hurley
In the last couple days, a few troubling bugs have been uncovered using Horizon that point to a much deeper problem of admin-ness in Essex. First, the two most recent bugs: 1. https://bugs.launchpad.net/keystone/+bug/968696 Summary: having an admin role on any tenant gives you admin rights in